From f6c5c1680b50a24d1e77c7843e05ae39e847ae94 Mon Sep 17 00:00:00 2001 From: martinfrancois Date: Mon, 21 Sep 2026 05:00:03 +0200 Subject: [PATCH 1/2] ci: install commitlint with pnpm This repository has no package.json and no Node dependencies of its own. The only npm usage is installing commitlint into a scratch directory during CI, so that install now runs through pnpm instead. scripts/install_commitlint.sh and scripts/commitlint_release_pr.sh call pnpm --dir where they called npm --prefix. The two workflows that run them, commitlint.yml and release-please.yml, activate pnpm 12.4.1 with corepack after actions/setup-node, because corepack needs Node on PATH and the scripts need pnpm. 12.4.1 is older than the seven day minimumReleaseAge this repository sets for Renovate. The newer pnpm releases are not. The pinned commitlint versions stay where they were. This changes the package manager, not the dependency. The Renovate custom manager that keeps those pins current matches the package lines, which this change leaves untouched, and it reports the same versions before and after. --- .github/workflows/commitlint.yml | 5 +++++ .github/workflows/release-please.yml | 6 ++++++ scripts/commitlint_release_pr.sh | 2 +- scripts/install_commitlint.sh | 2 +- 4 files changed, 13 insertions(+), 2 deletions(-) diff --git a/.github/workflows/commitlint.yml b/.github/workflows/commitlint.yml index 82469c2..8d1a009 100644 --- a/.github/workflows/commitlint.yml +++ b/.github/workflows/commitlint.yml @@ -39,6 +39,11 @@ jobs: with: node-version: "24" + - name: Enable pnpm + run: | + corepack enable + corepack prepare pnpm@12.4.1 --activate + - name: Prepare commitlint run: scripts/install_commitlint.sh diff --git a/.github/workflows/release-please.yml b/.github/workflows/release-please.yml index 6461d46..759b5c2 100644 --- a/.github/workflows/release-please.yml +++ b/.github/workflows/release-please.yml @@ -118,6 +118,12 @@ jobs: with: node-version: "24" + - name: Enable pnpm + if: ${{ steps.release-pr.outputs.found == 'true' }} + run: | + corepack enable + corepack prepare pnpm@12.4.1 --activate + - name: Mark release PR commitlint pending if: ${{ steps.release-pr.outputs.found == 'true' }} env: diff --git a/scripts/commitlint_release_pr.sh b/scripts/commitlint_release_pr.sh index b1b7aca..e57b8a6 100755 --- a/scripts/commitlint_release_pr.sh +++ b/scripts/commitlint_release_pr.sh @@ -20,7 +20,7 @@ commitlint_home="${RUNNER_TEMP:-$(mktemp -d)}/commitlint" mkdir -p "$commitlint_home" printf '{"private":true}\n' > "$commitlint_home/package.json" cp commitlint.config.cjs "$commitlint_home/commitlint.config.cjs" -npm --prefix "$commitlint_home" install --silent --ignore-scripts \ +pnpm --dir "$commitlint_home" add --silent --ignore-scripts \ @commitlint/cli@21.2.2 \ @commitlint/config-conventional@21.2.2 diff --git a/scripts/install_commitlint.sh b/scripts/install_commitlint.sh index db90a49..bc8adef 100755 --- a/scripts/install_commitlint.sh +++ b/scripts/install_commitlint.sh @@ -5,7 +5,7 @@ commitlint_home="${RUNNER_TEMP:-$(mktemp -d)}/commitlint" mkdir -p "$commitlint_home" printf '{"private":true}\n' > "$commitlint_home/package.json" cp commitlint.config.cjs "$commitlint_home/commitlint.config.cjs" -npm --prefix "$commitlint_home" install --silent --ignore-scripts \ +pnpm --dir "$commitlint_home" add --silent --ignore-scripts \ @commitlint/cli@21.2.2 \ @commitlint/config-conventional@21.2.2 From 56bd9f4ec4f6a0a1124e57a7ed78c851f2111571 Mon Sep 17 00:00:00 2001 From: martinfrancois Date: Mon, 21 Sep 2026 06:09:11 +0200 Subject: [PATCH 2/2] chore(renovate): keep the pnpm pin current Review of this PR found that corepack prepare pnpm@x is an exact pin no Renovate manager reads. A third regex manager now tracks it against the npm registry, and the workflows say why corepack is only good for the pinned Node major. --- .github/workflows/commitlint.yml | 2 ++ .github/workflows/release-please.yml | 2 ++ renovate.json | 12 ++++++++++++ 3 files changed, 16 insertions(+) diff --git a/.github/workflows/commitlint.yml b/.github/workflows/commitlint.yml index 8d1a009..6eb5e8b 100644 --- a/.github/workflows/commitlint.yml +++ b/.github/workflows/commitlint.yml @@ -41,6 +41,8 @@ jobs: - name: Enable pnpm run: | + # Node 24 ships corepack; later Node majors do not, so a node-version bump + # must install pnpm another way. corepack enable corepack prepare pnpm@12.4.1 --activate diff --git a/.github/workflows/release-please.yml b/.github/workflows/release-please.yml index 759b5c2..2e9f088 100644 --- a/.github/workflows/release-please.yml +++ b/.github/workflows/release-please.yml @@ -121,6 +121,8 @@ jobs: - name: Enable pnpm if: ${{ steps.release-pr.outputs.found == 'true' }} run: | + # Node 24 ships corepack; later Node majors do not, so a node-version bump + # must install pnpm another way. corepack enable corepack prepare pnpm@12.4.1 --activate diff --git a/renovate.json b/renovate.json index c9c478d..5fc1840 100644 --- a/renovate.json +++ b/renovate.json @@ -55,6 +55,18 @@ "datasourceTemplate": "npm", "packageNameTemplate": "tessl", "versioningTemplate": "semver" + }, + { + "customType": "regex", + "managerFilePatterns": [ + "/^\\.github/workflows/(?:commitlint|release-please)\\.yml$/" + ], + "matchStrings": [ + "corepack prepare pnpm@(?\\d+\\.\\d+\\.\\d+)" + ], + "depNameTemplate": "pnpm", + "datasourceTemplate": "npm", + "versioningTemplate": "semver" } ], "packageRules": [